Security Research & Insights
Research, guides, and field notes on offensive security.

security research
Four Coldcard Bugs, Reported and Fixed
Reviewing the Coldcard Q's dice-roll entropy turned up four bugs in its seed, multisig, USB, and QR paths. Reported to Coinkite and fixed in 5.6.1 / 1.5.1Q.
12 min read
Read 
compliance
DORA Penetration Testing: What Financial Institutions Need to Know
DORA requires threat-led penetration testing for financial entities in the EU. Here's what TLPT actually involves, how long it takes, and how to prepare.
10 min read
Read